%0 Journal Article
%T Design and Research of an Alert Clustering Algorithm Based on Search Tree and an Alert Classified Method Based on Bayesian Classifier
基于搜索树的告警高效聚类算法和Bayes分类器的设计和研究
%A XIAO Zheng
%A WANG Jian-Xing
%A HOU Zi-Feng
%A WEI Wei
%A
肖政
%A 王建新
%A 侯紫峰
%A 韦卫
%J 计算机科学
%D 2006
%I
%X How to effectively find out valuable abnormal behaviors from the numerous alarms and logs produced by all kinds of security products everyday, all of them must be analyzed and the true and non-redundant information should be extracted, which is helpful to find the real problem and then correcting actions can be taken to protect the safety of systern. This is one of the biggest challenges which IDS is facing. In this paper, taking into account search tree which can decrease searching space and overlay vector, an alert clustering algorithm based on search tree is presented. So as to classify new alert and can have correlation with other alert, an alert classified method based on Bayesian classifier is emphatically proposed. At last, KDD Cup 1999 Data is used to evaluate the performance of algorithm, and the experiment results show the high efficiency of the algorithm. The applications of them to Multi-information-source intelligential security auditing system indicate that they will have a good future for implementation.
%K Alert correlation
%K Bayesian classifier
%K Search tree algorithm
%K Clustering
告警关联
%K 贝叶斯分类器
%K 搜索树算法
%K 聚类
%U http://www.alljournals.cn/get_abstract_url.aspx?pcid=5B3AB970F71A803DEACDC0559115BFCF0A068CD97DD29835&cid=8240383F08CE46C8B05036380D75B607&jid=64A12D73428C8B8DBFB978D04DFEB3C1&aid=5D6BEC58D1B68566&yid=37904DC365DD7266&vid=27746BCEEE58E9DC&iid=5D311CA918CA9A03&sid=6235172E4DDBA109&eid=5D9D6A8FC2C66FD8&journal_id=1002-137X&journal_name=计算机科学&referenced_num=2&reference_num=27